Authentication Policy with Captive portal MFA not prompting for re-authentication
512
Created On 10/31/22 11:08 AM - Last Modified 11/17/25 20:38 PM
Symptom
- While Attempting to access the resource referenced in the Authentication Policy rule for the second time you will be unable to see the prompt requiring you to authenticate
Environment
- Global protect
- Captive portal
- Authentication policy
Cause
- Unable to prompt for re-authentication via Authentication Policy with MFA(captive portal) Due to default timeout value set in the Authentication policy rule as 60 minutes
Resolution
- Need to reduce the timeout value set in the Authentication policy rule as per the requirement
- By default, the timeout value is set to 60 minutes.
Additional Information
- GlobalProtect: Authentication Policy with MFA
- Authentication Policy
- HOW TO CONFIGURE AUTHENTICATION POLICIES WHEN CAPTIVE PORTAL WITH SAML AUTHENTICATION IN PALO ALTO NETWORKS FIREWALL.